|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
From: Nick FitzGerald (nick
virus-l.demon.co.uk)Date: Sun Sep 09 2001 - 17:47:16 CDT
"anonymous <rst
coders.com> wrote:
> At the 5th of September Qualys released a Security Warning regarding a Linux
> based virus. This virus was called the "Remote Shell Trojan" (RST) and it
> attacks Linux ELF binaries. It has replicating abilities: when run it will
> infect all binaries in /bin and the current working directory. Besides that
> it also spawns a process listening on UDP port 5503. When a properly crafted
> packet is received by this process it will connect back with a system shell.
<<snip>>
To the best of my knowledge, neither Qualys nor yourselves (or anyone
else) has provided samples of this virus to the usual antivirus
research community. You are more likely to have a fix for this virus
reach where it is needed through those established and now fairly
well-honed delivery systems than by posting to a public mailing list.
If you or Qualys wish to provide such samples to the antivirus
research community, please send the samples where you would normally
send virus samples. If you do not have a preferred vendor or
vendors, here is a list of the sample submission addresses of the
better known antivirus developers -- please choose the vendor(s) you
feel happy trusting such code to and supply them with a sample:
Command Software <virus
commandcom.com>
Computer Associates (US) <virus
cai.com>
Computer Associates (Vet/IPE) <ipevirus
vet.com.au>
DialogueScience (Dr.Web) <Antivir
dials.ru>
Eset (NOD32) <trnka
eset.sk>
F-Secure Corp. <samples
f-secure.com>
Frisk Software <viruslab
complex.is>
Kaspersky Labs <newvirus
avp.ru>
Network Associates (US) <virus_research
nai.com>
Norman (NVC) <analysis
norman.no>
Sophos Plc. <support
sophos.com>
Symantec <avsubmit
symantec.com>
Trend Micro <virus_doctor
trendmicro.com>
-- Nick FitzGerald Computer Virus Consulting Ltd. Ph/FAX: +64 3 3529854
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]